Try Our New BETA Version
GO
(navigation image)
Home Animation & Cartoons | Arts & Music | Community Video | Computers & Technology | Cultural & Academic Films | Ephemeral Films | Movies | News & Public Affairs | Prelinger Archives | Spirituality & Religion | Sports Videos | Television | Videogame Videos | Vlogs | Youth Media
Search: Advanced Search
Anonymous User (login or join us)
Upload

View movie

item imageitem imageitem imageitem image

View thumbnails

Play / Download (help[help])

(12.2 M)Ogg Video
(17.3 M)h.264
(79.7 M)QuickTime


All Files: HTTPS Torrent (2/0)
[Attribution-Share Alike 3.0]

Resources

Bookmark

Veronica KovahDynamic Malware Analysis Day 2 Part 18 - Malware Functionality Backdoor Overview

something has gone horribly wrong 8-p
Prefer flash? · Embed · Questions/Feedback?

Get the class materials to follow along at http://www.opensecuritytraining.info/MalwareDynamicAnalysis.html
Follow us on Twitter for class news @OpenSecTraining.

This introductory malware dynamic analysis class by Veronica Kovah is dedicated to people who are starting to work on malware analysis or who want to know what kinds of artifacts left by malware can be detected via various tools. The class will be a hands-on class where students can use various tools to look for how malware is: Persisting, Communicating, and Hiding

We will achieve the items above by first learning the individual techniques sandboxes utilize. We will show how to capture and record registry, file, network, mutex, API, installation, hooking and other activity undertaken by the malware. We will create fake network responses to deceive malware so that it shows more behavior. We will also talk about how using MITRE's Malware Attribute Enumeration & Characterization (MAEC - pronounced "Mike") standard can help normalize the data obtained manually or from sandboxes, and improve junior malware analysts' reports. The class will additionally discuss how to take malware attributes and turn them into useful detection signatures such as Snort network IDS rules, or YARA signatures.

Dynamic analysis should always be an analyst's first approach to discovering malware functionality. But this class will show the instances where dynamic analysis cannot achieve complete analysis, due to malware tricks for instance. So in this class you will learn when you will need to use static analysis, as offered in follow the follow on Introduction to Reverse Engineering and Reverse Engineering Malware classes.

During the course students will complete many hands on exercises.

Course Objectives:
* Understand how to set up a protected dynamic malware analysis environment
* Get hands on experience with various malware behavior monitoring tools
* Learn the set of malware artifacts an analyst should gather from an analysis
* Learn how to trick malware into exhibiting behaviors that only occur under special conditions
* Create actionable detection signatures from malware indicators

This class is recommended for a later class on malware static analysis. This is so that students understand both techniques, and utilize the technique which gives the quickest answer to a given question.



This movie is part of the collection: OpenSecurityTraining.info

Producer: Veronica Kovah
Keywords: OpenSecurityTraining.info; Reverse Engineering; Malware; Malware Analysis; Dynamic Analysis; Malware Dynamic Analysis; VirtualBox; PE; Portable Executable; File Identification; Windows Libraries; Windows Processes; Windows Registry; Windows Services; Networking; Wireshark; Malware Terminology; Behavioral Analysis; Malware Sandbox; CuckooBox; Malware Persistence; AutoRuns; Malware Maneuvering; DLL Injection; API Tracing; Win32Override; RegShot; ProcMon; Process Monitor; Poison Ivy RAT; YARA; Computer security class; Computer Security; Cyber Security; CyberSecurity; Host Security; Training; Education; Multi-day-class; Multi-day-training; Classes; Computer; Computers; Security; Technology

Creative Commons license: Attribution-Share Alike 3.0


Individual Files

Movie Files Thumbnail Animated GIF QuickTime h.264 Ogg Video
PR_DynamicMalwareAnalysis-D2P18-Malware_Functionality_Backdoor_Overview.mov 6.3 KB 
52.4 KB 
79.7 MB 
17.3 MB 
12.2 MB 
Information FormatSize
Day2Part18DynamicMalwareAnalysis_files.xml Metadata [file] 
Day2Part18DynamicMalwareAnalysis_meta.sqlite Metadata 27.0 KB 
Day2Part18DynamicMalwareAnalysis_meta.xml Metadata 5.2 KB 
Other Files Archive BitTorrent
Day2Part18DynamicMalwareAnalysis_archive.torrent 6.8 KB 

Be the first to write a review
Downloaded 363 times
Reviews


Terms of Use (31 Dec 2014)